WebCull
cli

E2EE And Safety

Use CLI commands safely with encrypted accounts and user-managed keystore pipelines.

Encrypted Account Commands Keep Secrets Local

For E2EE accounts, the CLI accepts one passphrase only from non-TTY stdin when --e2ee-passphrase-stdin is explicitly present. Never put a passphrase in command arguments, environment variables, config files, logs, examples, or API requests.

Keep your E2EE passphrase in a keystore you choose and manage. That keystore pipes the passphrase directly into the CLI process only when encrypted fields are required. The CLI persists neither value after the process exits.

Decrypt And Encrypt Only In The CLI Process

Search
Encrypted accounts use limited local decrypted search when bookmark text needs to be searched.
Get
Requested encrypted fields are decrypted locally when you provide the passphrase.
Writes
Edited encrypted fields are encrypted locally before being sent to WebCull.
Graph
Graph commands exclude notes unless you request extra fields.

Pipe Passphrases From Your Own Keystore

# Unsafe
webcull bookmarks get --account <account-hash> --ids 2302 --e2ee-password secret

# macOS Keychain
security find-generic-password -a "$USER" -s webcull-e2ee -w |
  webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin

# Windows PowerShell with Microsoft.PowerShell.SecretManagement
Get-Secret -Name webcull-e2ee -AsPlainText |
  webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin

# Linux Secret Service
secret-tool lookup service webcull-e2ee account "$USER" |
  webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin

Each encrypted operation requires an explicit account and --e2ee-passphrase-stdin. The keystore process writes one passphrase directly to the CLI pipe, so an agent can run the command without receiving or displaying the secret.

The credential names in these examples are placeholders. Configure the entry in your own keystore and use the matching name in the retrieval command. The CLI rejects TTY input, empty input, attached option values, and multiline input.

Next step agent Overview Choose the right WebCull CLI agent workflow and follow conservative limits, pacing, write, and E2EE rules.